People are paying pentesters because their payer’s policy asks them to. Of course there will be a huge market for someone with an alleged certification to run automated tools, the value is in the box checking and report generation, not the bespoke broken website fixing.
Obviously this is a bit of a reaching statement, some organizations understand the legal, career, and regulatory risk and proactively do it. In every org I've sat down with the head to explain those risks, I can see how it can be made priority and budget.
These operators have no incentive to invest in proper skills. So they don't. They can charge almost anything they like. And sure enough, they do.
In an industry with such massive vendor lock-ins and regulatory capture regimes, organisationally you get to shovel a lot of money for sub-par pentests. The appetite to have yet another one, even from a known-good and reasonably priced provider, is quite hard to come by. After all, these approved providers will REFUSE to even look at a third-party pentest report, let alone let one guide their own testing.
So in aggregate the existence of these approved providers and their level of competence degrades the security posture of entire business domains.
Macchiavelli would have been proud.